| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9qv9-8xv6-5p35 | phpMyFAQ: Unauthenticated Password Reset Endpoint Allows User Enumeration and Forced Password Change Without Token Validation |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 28 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attackers to change account passwords without token validation. Attackers can enumerate valid username and email pairs and force immediate password changes by sending PUT requests to the /api/index.php/user/password/update endpoint, causing account disruption and invalidating legitimate user credentials. | |
| Title | phpMyFAQ - Unauthenticated Password Reset via User Password Update Endpoint | |
| First Time appeared |
Phpmyfaq
Phpmyfaq phpmyfaq |
|
| Weaknesses | CWE-640 | |
| CPEs | cpe:2.3:a:phpmyfaq:phpmyfaq:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Phpmyfaq
Phpmyfaq phpmyfaq |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-28T15:35:36.744Z
Reserved: 2026-04-04T12:32:50.477Z
Link: CVE-2026-35676
Updated: 2026-05-28T15:35:20.528Z
Status : Received
Published: 2026-05-28T16:16:21.923
Modified: 2026-05-28T17:16:20.443
Link: CVE-2026-35676
No data.
OpenCVE Enrichment
Updated: 2026-05-28T16:30:15Z
Github GHSA